Authentication Device for Control Program Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In control systems, existing digital signature methods are ineffective in detecting tampering or destruction of control programs when the development device itself malfunctions, as they cannot verify the authenticity of the control program created in a sound environment.

Innovation Solution

A control system configuration that includes an authentication device with an authentication list to verify the soundness of the development device and generate a signature for the control program, ensuring the program's integrity by checking accompanying information and using separate storage for signatures to prevent tampering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a digital signature is used to verify control program integrity, then tampering detection is improved, but the system cannot detect abnormalities in the development device itself

Engineering Contradiction:
Improvecontrol program integrity verificationVSAvoidundetectable development device malfunction
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by having the authentication device verify the development device's normality and generate authentication information before the control program is signed. This includes checking the development device's environment and state, and creating authentication information that binds the program signature to the verified development device state, preventing undetectable tampering

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication device serves as an intermediary between the development device and the control program verification process. It generates authentication information that mediates the trust relationship, verifying both the development device's normality and the program's integrity, thereby solving the problem of undetectable development device abnormalities

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the development device is used to generate digital signatures, then program distribution efficiency is improved, but the risk of program destruction or tampering increases

Engineering Contradiction:
Improvecontrol program distribution efficiencyVSAvoidprogram protection against destruction
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the signature generation process into two independent components: the development device generates the program signature, while the authentication device separately generates authentication information verifying the development device's normality. This segmentation allows efficient program distribution while adding a layer of protection against development device abnormalities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication device acts as an intermediary that verifies the development device's state before accepting program signatures. It creates authentication information that binds the signature to the verified state, preventing program destruction or tampering while maintaining distribution efficiency

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If authentication information is stored in the same location as control programs, then storage simplicity is improved, but vulnerability to tampering increases

Engineering Contradiction:
Improvestorage structure simplicityVSAvoidtampering vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent segments storage into separate locations: control programs are stored in one location while authentication information is stored in a different, protected location. This physical or logical separation prevents tampering with both programs and authentication data, while the authentication information remains readily accessible for verification

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9965625B2Control system and authentication device
Publication Date: 2018.05.08 HITACHI LTD
  • US9965625B2 patent drawing
  • US9965625B2 patent drawing
  • US9965625B2 patent drawing

AI summary

Provided are a control system and an authentication device capable of detecting abnormality of a development device for distributing a control program and of preventing destruction and tampering of the program caused by the abnormality. To solve the above problem, there is provided: a control device that controls a controlled object; a development device that manages a plurality of control programs executed by the control device and sends the predetermined control program and information accompanying the control program to the network; and an authentication device having an authentication list storing the information accompanying the control program in association with the control program. Upon receiving the control program and the information accompanying the control program from the development device, the authentication device performs authentication whether or not the development device is normal by checking the accompanying information received from the development device with the information stored in the authentication list.